SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26404

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

MEDIUM 5.5EPSS 0.18%

Does this matter?

Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.

Description

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.18% probability · 8th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
amd/epyc 7003 firmware · amd/epyc 7313 firmware · amd/epyc 7313p firmware · amd/epyc 7343 firmware · amd/epyc 7373x firmware · amd/epyc 73f3 firmware · amd/epyc 7413 firmware · amd/epyc 7443 firmware · amd/epyc 7443p firmware · amd/epyc 7453 firmware · amd/epyc 7473x firmware · amd/epyc 74f3 firmware · amd/epyc 7513 firmware · amd/epyc 7543 firmware · amd/epyc 7543p firmware · amd/epyc 7573x firmware · amd/epyc 7643 firmware · amd/epyc 75f3 firmware · amd/epyc 7663 firmware · amd/epyc 7713 firmware · +3 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.